Skip to main content
Administrator Guide
Last Updated: 2026-07-24
Steps: Set Up Sana for Workday

Steps: Set Up Sana for Workday

You might need to take additional steps to enable this feature based on your organization's subscription service agreement. Your organization is either on the Main Service Agreement (MSA) or the Universal Main Service Agreement (UMSA). To determine your organization's subscription service agreement:
  1. Select your profile avatar on Workday Community.
  2. Select
    Profile
    .
  3. On your profile page, select your organization's name, which is beneath your name and next to your job title.
  4. View your
    Subscription Service Agreement
    value.
If the value is:
UMSA is required for non-production and production tenants for Workday-Built agents. UMSA is not required for non-production tenants for self-built agents.
For information about how using agents impacts your Flex Credits, see: Workday Flex Credits Community page.
To use this functionality, you must:
  • Sign the Universal Main Subscription Agreement (UMSA).
    When you sign the agreement, Workday provides your organization with complimentary Flex Credits that you can use towards Sana Core for Workday. Once you reach the allotted complimentary Flex Credit consumption, you must sign the Workday Flex Credits and Platform Entitlement Policy to continue to use Sana Core for Workday.
  • Purchase the Core Human Capital Management or Core Financials SKU. This only applies to Sana Core.
  • Sign the Workday Flex Credits and Platform Entitlement Policy. This only applies to Sana Enterprise.
  • Purchase the Sana Enterprise SKU. This only applies to Sana Enterprise.
Security: These domains in the System functional area:
  • Sana Agent User Provisioning
  • Sana Enterprise
  • Security Activation
  • Security Configuration
To ensure security setup for Sana and the related AI agents is complete, Workday sends notifications to administrators. We notify:
  • Workday security administrators to complete the
    Set Up AI Admin Security Permissions
    task.
  • Agent System of Record administrators to configure and activate the
    Self-Service Agent
    .
  • Sana administrators to optionally configure or modify default settings in the
    Sana Workspace
    .
  • User provisioning administrators to provision employees to
    Sana
    .
  1. Edit Domain Security Policies.
    Configure the
    Sana Enterprise
    domain in the System functional area.
    This step is required if your organization purchased the Sana Enterprise SKU. This domain configuration determines who can use cross-system connections and Sana Enterprise features.
  2. (Optional) Access the
    Set Up Security Groups for User Provisioning
    task. If you only want particular security groups to be available for Sana provisioning, add rows to the grid and select the groups to enable on the
    Security Groups
    prompt.
    Security:
    Set Up: User Provisioning
    domain in the System and User Provisioning functional areas.
  3. Provision users to Sana Workspace.
    We notify user provisioning administrators to provision users to the Sana Workspace.
    1. In Workday, open the
      Action Required: Provision Users to Sana Workspace
      notification from the bell icon.
    2. Click the link in the notification to open the
      User Provisioning Workspace
      .
    3. On the
      Products
      page, click
      Configure
      in the
      Sana
      tile.
    4. In the
      Provision Users
      section, click
      Edit Provisioning Group
      .
    5. In the
      Using Workday Security Groups
      prompt, select either:
      • All
        to provision all users for Sana.
      • Individual security groups to provision. You can only select individual security groups if you set them up for user provisioning on the
        Set Up Security Groups for User Provisioning
        task.
    6. Click
      Update Provisioning Group
      .
    7. Click
      Preview and Enable Sync
      .
    8. Review the users who will be provisioned, select the confirmation check box, and click
      Enable Sync
      .
    After sync is enabled, users in the selected security groups are automatically provisioned and can sign in to the Sana Workspace.
  4. Enable access to the Sana Workspace from Workday.
    To make it easy for users to find and access the Sana Workspace from your Workday tenant, enable the
    Sana
    card on the Home page:
    1. On the Home Cards Workspace, click
      Home
      .
    2. Click
      Cards
      .
    3. Click
      Edit Work Tools
      .
    4. In the
      Edit Work Tools
      pop up, add a row to the grid.
    5. In the
      Name
      field, enter
      Sana
      .
    6. Click
      OK
      .
  5. (Optional) Configure the Sana Workspace.
    1. From the Sana Workspace, click the arrow next to the workspace name in the navigation menu.
    2. Click
      Workspace Settings
      .
    3. (Optional) Configure optional settings. You can:
    • Disable web search.
    • Disable intercom support chat.
    • Disable specific third-party connectors. (Sana Enterprise only.)
    • Restrict agentic actions to approved email domains. (Sana Enterprise only.)
Users can immediately access Sana from Workday and use Sana capabilities.